The SOC Manager is responsible for the effective operation, performance and continuous improvement of the Security Operations Centre (SOC) while working closely with the Head of Cybersecurity and Technology teams to reduce organizational cyber risk.
The role will own the day-to-day operation of the SOC and lead a team of high-performing SOC analysts to create an accountable and cooperative SOC culture.
Duties
Operational leadership to ensure 365 x 24 x 7 security monitoring, detection, investigation and incident response.
Develop and maintain effective SOC operating procedures, process and playbooks.
Lead, coach and develop SOC team.
Conduct regular 1-2-1’s, performance reviews and development planning.
Identify skills gaps and appropriate training to build analyst capabilities across SIEM, incident response, threat hunting and security investigation.
Support recruitment and onboarding of SOC personnel as required.
Establish appropriate shift patterns and on-call operational coverage.
Manage SOC workload, prioritisation and resource allocation.
Establish and report meaningful SOC operational metrics.
Ensure consistent application of incident investigation and response procedures
Provide operational leadership during major cyber incidents.
Qualifications
Technical Knowledge, Skills and Abilities:
Minimum 8–10 years SOC experience with progressive responsibility in security operations.
Significant SOC leadership, including proven experience managing security analysts and/or leading SOC teams of 8–10 members.
Significant experience working within a SOC with proven experience of managing security analysts and/or SOC teams.
Strong practical experience with SIEM platforms, security monitoring and alert investigation.
Strong understanding of incident response and security investigation methodologies.
Experience managing major incidents.
Strong understanding of attacker TTP’s, threat hunting and detection engineering.
Strong people man